RISK ASSESSMENT ENGINE

A system, method and computer program product for assessing risk of a process through a set of entities identified as utilizing personal data needing protection from misuse and wrongful disclosure comprising mapping the identified process including identifying a purpose of the identified process and...

Full description

Saved in:
Bibliographic Details
Main Authors Switalski, Maciej, Furtsch, Joanne, Green, Joseph Jacob, Casey, Christopher P, Wandall, Hilary M, Gu, Neng, Le, Binh P
Format Patent
LanguageEnglish
Published 10.12.2020
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:A system, method and computer program product for assessing risk of a process through a set of entities identified as utilizing personal data needing protection from misuse and wrongful disclosure comprising mapping the identified process including identifying a purpose of the identified process and a sensitivity of that purpose; identifying data elements including the utilized personal data and including a volume and sensitivity of those identified data elements; identifying data types including the utilized personal data and including a volume and sensitivity of those identified data types; identifying data subjects about whom data is involved in the process including a volume and sensitivity of those identified data subjects; and identifying the set of entities involved in the process and their locations; and identifying data flows among the set of entities involved in the process; and applying a set of rules against the mapped process to provide a risk assessment of the mapped process based on the risk sensitivity of the process purpose, sensitivity and volume of each data element, data type, and data subject, risk related to the entity locations and data flows among the entity locations.
Bibliography:Application Number: US202016894836